Security1 publisherNot yet confirmed elsewhere2 min readPublished
Ten agencies tie China-linked intrusions across several sectors to Integrity Technology Group
Integrity Technology Group, a government-linked Chinese firm, enables China-linked hackers to breach US and foreign networks, ten agencies said. The advisory treats the firm and its crews as one set of actors, so a single hunt can span sectors.
The Watch · Security desk
What happened
- The crews combine large-scale botnets, VPN infrastructure, living-off-the-land techniques and repositories of network exploitation tools, the advisory says.
- Victims span US government, critical manufacturing, healthcare and IT, plus law enforcement, education, religious groups and organizations in Southeast Asia, Africa and North America.
- The advisory's evidence was recovered from, and observed during, multiple FBI investigations related to Integrity Tech.
- Integrity Tech is run for profit, acquires or builds cyber tools for sale as well as use, and employs people who break into victim networks directly.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability One sweep against infrastructure Integrity Tech hosts can surface intrusions a defender had filed under different actor names, because several crews draw on the same supplier.
- exposure A clean result against the Integrity Tech indicators does not clear a network, since the advisory says the same crews also run operations not associated with the firm.
- decision Law enforcement, education and religious organizations are on the victim list, so the hunt request applies to them as much as to the four named critical infrastructure sectors.
The advisory says activity matching the crews Integrity Tech enables is publicly known as Flax Typhoon, Ethereal Panda and Red Juliett, among other names [10]. A team that keeps separate case files under two of those names may be tracking customers of the same supplier. The agencies also warn that vendor groupings "may not be a 1:1 correlation to the US Government's methodology" [12]. Merging cases on a vendor label alone can pull in activity the government groups differently.
The advisory supports a cross-sector hunt for one toolkit, but its wording stops short of treating every match as the same operator. It calls the combination of tools unique [2]. It says the techniques themselves "are not unique to Chinese threat actors" [3]. On those terms, one botnet address or one living-off-the-land command in a log is a lead to check against the indicator list. The agencies publish that list as a separate download [13].
I'd expect the hosted infrastructure to be the part that repeats from victim to victim. Integrity Tech acquires and hosts infrastructure for the crews it enables [15]. Its services feed what the advisory calls "the larger Chinese cyber ecosystem, which aims to exfiltrate sensitive data from victims around the world" [14].
The FBI, CISA and NSA signed with the national cyber agencies of the UK, Australia, Canada and New Zealand [7]. Japan's National Police Agency and National Cybersecurity Office signed, as did Spain's Centro Nacional de Inteligencia [7]. Ten organisations in seven countries are on it [16]. They ask defenders to hunt for compromises from this activity and to harden against it and other Chinese government-linked targeting [8].
What to watch
- Whether firms that track Flax Typhoon, Ethereal Panda and Red Juliett re-map those clusters to the government's Integrity Tech grouping.
- Hunt results from the named victim sectors that match the published indicators, which would show how far one supplier's infrastructure reaches.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence58
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Integrity Technology Group, a China-based company with links to the Chinese government, enables China-linked threat actors to exploit US and foreign organization networks across multiple sectors using various tools and techniques.
- [2]
The threat actors use a unique combination of large-scale botnets, virtual private network (VPN) infrastructure, living-off-the-land (LOTL) techniques, and repositories of computer network exploitation (CNE) tools.
- [3]
Although these techniques are not unique to Chinese threat actors, the advisory details how the threat actors use them to support CNE activity.
- [4]
The threat actors targeted victims across multiple US critical infrastructure sectors, including Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology; they also targeted victims in US law enforcement, education, and religious organizations, as well as organizations across Southeast Asia, Africa, and North America.
- [5]
The advisory analyses TTPs and IOCs from Integrity Technology Group and the threat actors they enable, referring to them collectively as 'the threat actors'.
- [6]
The information in the advisory originates from technical evidence recovered from, and observed during, multiple FBI investigations related to Integrity Technology Group.
- [7]
The authoring organizations are the FBI, CISA, NSA, NCSC-UK, ASD's ACSC, the Canadian Centre for Cyber Security, Japan's National Police Agency and National Cybersecurity Office, New Zealand's NCSC-NZ, and Spain's Centro Nacional de Inteligencia.
- [8]
The authoring organizations urge network defenders to hunt for potential compromises from this activity and to better protect against this threat activity and other Chinese government-linked cyber targeting.
- [9]
Integrity Tech is a China-based for-profit company with links to the Chinese government that employs individuals who support malicious cyber activity, including acquiring or building cyber tools for use and sale and compromising networks across global victims.
- [10]
The threat actors enabled by Integrity Tech use TTPs consistent with the cyber activity publicly known as Flax Typhoon, Ethereal Panda, and Red Juliett, among others.
- [11]
The threat actors enabled by Integrity Tech may also perform activity not associated with Integrity Tech.
- [12]
Cybersecurity companies have different methods of tracking and attributing cyber actors, and these may not be a 1:1 correlation to the US Government's methodology and understanding for all activity related to these groupings.
- [13]
The advisory provides indicators of compromise, including a downloadable copy of the IOCs.
- [14]
The services provided by Integrity Tech contribute to the larger Chinese cyber ecosystem, which aims to exfiltrate sensitive data from victims around the world.
- [15]
Integrity Tech employs individuals who acquire and host infrastructure in support of malicious cyber activity.
- [16]
Ten authoring organizations from seven countries signed the advisory.
Sources
1 independent publisher whose own reporting we read for this story.
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- BotnetsFollow
- State-Linked Cyber EspionageFollow
- Living off the landFollow
- Critical infrastructure securityFollow
- Joint cybersecurity advisoriesFollow
Entities
- Integrity Technology GroupFollow
- Federal Bureau of InvestigationFollow
- CISAFollow
- National Security AgencyFollow
- UK NCSCFollow
- Australian Signals Directorate's Australian Cyber Security CentreFollow
- Canadian Centre for Cyber SecurityFollow
- National Police Agency (Japan)Follow
- National Cybersecurity Office (Japan)Follow
- NCSC-NZFollow
- Centro Nacional de InteligenciaFollow
- Flax TyphoonFollow
- Ethereal PandaFollow
- Red JuliettFollow
- MicroScanFollow
- MITRE ATT&CKFollow